aliteq.

Security & Compliance · for AI startups and small SaaS

Security and compliance, priced for AI startups

Your first enterprise customer wants a SOC 2, a security questionnaire, a DPA or answers on the EU AI Act. What each one is, who actually asks for it, what it costs in year one, and the fixes that come before any audit. Every number sourced and dated.

Section editor Cipher · updated September 2026

Hand-drawn illustration of an auditor with a magnifying glass inspecting a startup laptop inside a padlock-shaped doorway
$15.5k–$50k
SOC 2 Type 2 audit fee at a specialist CPA firm
3–6 months
to a first SOC 2 Type 1 report
80%
of companies using AI get customer risk questions about it
2 Dec 2027
when the AI Act's high-risk rules now start

I read security the way an attacker reads it: follow the incentives, find where it breaks. In compliance, the incentives point one way. Almost every guide you'll find is written by a company that sells audits, compliance software or consulting, and the advice bends toward the product.

This section is the other kind. It's written for the team I see most often in 2026: a handful of people who call the OpenAI or Claude API, run on Supabase, Vercel or Lovable, and have just been asked for a SOC 2 report or a forty-page questionnaire. Every figure here was read on the source's own page, dated, and labelled with who published it. For transparency: aliteq runs on Supabase and Cloudflare, was built with AI coding tools, and has no SOC 2 report of its own.

Which frameworks you'll actually be asked for

Most small companies meet these in the same order: a customer's security questionnaire first, then a request for a SOC 2 report, then a data processing agreement if they're in Europe, and a HIPAA business associate agreement if health data is involved. The EU AI Act and NIS2 arrive through contract clauses, not audits.

What each one is, and who asks

SOC 2 Type 1

Required by law?
No, voluntary
Who typically asks
US enterprise security and procurement teams
First-year cost (USD)
Audit fee $10k–$35k (specialist firm)
Time to have it
3–6 months

SOC 2 Type 2

Required by law?
No, voluntary
Who typically asks
The same buyers, especially at renewal
First-year cost (USD)
Audit $15.5k–$50k; all-in ~$20k–$80k (vendor estimates)
Time to have it
6–12+ months

ISO 27001

Required by law?
No, voluntary
Who typically asks
Often EU, UK and APAC buyers
First-year cost (USD)
~$6.6k–$66k overall (converted from £5k–£50k)
Time to have it
About 6 months

HIPAA BAA

Required by law?
Yes, if you handle health data for a covered entity
Who typically asks
US healthcare providers and plans
First-year cost (USD)
Readiness $25k–$100k+ (vendor-reported)
Time to have it
Before any health data flows

GDPR DPA

Required by law?
Yes, if you process EU personal data for customers
Who typically asks
EU customers
First-year cost (USD)
No published range
Time to have it
Before any personal data flows

NIS2

Required by law?
Directly only for medium or larger firms in listed sectors
Who typically asks
In-scope EU customers, via supplier clauses
First-year cost (USD)
No per-company figure we could verify
Time to have it
In force; Denmark since 1 Jul 2025

EU AI Act

Required by law?
Yes, where you provide or deploy AI in the EU
Who typically asks
EU customers deploying your AI feature
First-year cost (USD)
No published range
Time to have it
Transparency applies since Aug 2026

Pen test

Required by law?
No
Who typically asks
Enterprise buyers; auditors accept it as evidence
First-year cost (USD)
Typically $5k–$15k
Time to have it
Weeks

Two things are worth knowing up front. First, no survey tells you which of these your particular buyer will ask for. The confident percentages you'll see quoted ("80% of enterprises require SOC 2") have no primary source I could find, so I don't repeat them. Ask the buyer. Second, the questionnaire usually comes before any of it: large-company surveys by the vendor Whistic found companies field dozens of security assessments a month, and a small team can answer most of one honestly before it holds any certificate.

What each one costs in year one

A first SOC 2 is the biggest line for most AI startups: compliance vendors put it at about $20,000–$80,000 all-in, with a specialist firm's Type 2 audit fee at $15,500–$50,000. ISO 27001 runs about $6,600–$66,000 overall. GDPR, NIS2 and the AI Act have no price tag: they cost you the work of meeting them.

Range bars of first-year compliance costs in USD: HIPAA readiness $25k–$100k+, SOC 2 all-in year one $20k–$80k, ISO 27001 overall $6.6k–$66k, SOC 2 Type 2 audit fee $15.5k–$50k, ISO 42001 audit $5k–$20k, pen test $5k–$15k.
First-year cost ranges as published, mostly by companies that sell compliance. GBP converted at the ECB rate of 25 Sep 2026. · aliteq research

Read these ranges knowing who wrote them. The SOC 2 figures come mainly from SOC2Auditors.org, an ad-supported directory of audit firms, and from platform vendors such as Drata. The ISO 27001 range is a UK consultancy's, converted from pounds. The HIPAA figure is from Secureframe, which sells HIPAA compliance. For SOC 2 in detail, including an estimator that builds your own number line by line, see SOC 2 for AI startups.

If your product uses AI, the audit-firm A-LIGN's 2026 benchmark is the useful context: of 1,043 companies surveyed, 80% of those using AI said customers ask them risk questions about it, and a third had no AI compliance strategy.

How long until you have something to show

A SOC 2 Type 1 takes about three to six months, and a first Type 2 six to twelve months or more, because its observation window has to pass. ISO 27001 takes around six months to a first certificate. HIPAA and GDPR have no certificate to wait for: the agreement has to be signed before the data flows.

That makes the order of work simple. Sign the agreements the law requires first, answer the questionnaire in front of you honestly, and start the longest clock, the Type 2 window, as early as a real deal justifies.

The EU calendar you're already on

The EU AI Act applies generally since 2 August 2026, including the transparency duty to tell people they're talking to an AI. Its high-risk rules were moved by Regulation (EU) 2026/1744 to 2 December 2027 and 2 August 2028. GDPR has applied since 2018, and Denmark's NIS2 law since July 2025.

Timeline of EU compliance dates from 2018 to 2028, from GDPR on 25 May 2018 to the AI Act's high-risk rules for products on 2 August 2028.
Dates as published on EUR-Lex, the European Commission and SAMSIK, checked 27 September 2026. · aliteq research

Three things on that calendar trip small companies up:

  • Pages still claiming high-risk AI rules start in August 2026 are out of date. Regulation (EU) 2026/1744 moved them. What applies to a typical chatbot or generation feature today is Article 50 transparency, and generative systems already on the market before 2 August 2026 have until 2 December 2026 to mark their output.
  • NIS2 can reach you even if you're small. It applies directly only to medium-sized or larger companies in listed sectors, but Article 21 obliges those companies to secure their supply chain, so their supplier questionnaires and contract clauses land on you. Denmark's agency, SAMSIK, says the same about out-of-scope suppliers.
  • EU–US data transfers rest on a framework under appeal. The EU–US Data Privacy Framework is in force, and an appeal against it (case C-703/25 P) was lodged in October 2025. As of September 2026 I found no ruling. Standard contractual clauses remain the fallback.

What the fines look like

The caps are large: up to €35 million or 7% of turnover for the AI Act's prohibited practices, €20 million or 4% under GDPR, and €10 million or 2% for NIS2's essential entities. Real fines are usually far lower. One break for small companies: AI Act fines for SMEs are capped at the lower of the two amounts.

Bar chart of maximum fines in USD equivalent: AI Act prohibited practices about $39.9m, GDPR Art. 83(5) about $22.8m, AI Act other obligations about $17.1m, GDPR Art. 83(4) and NIS2 essential entities about $11.4m, NIS2 important entities about $7.98m, HIPAA yearly cap $2.19m.
Fine caps as written in each law; EUR converted at the ECB rate of 25 Sep 2026. Not legal advice. · aliteq research

Fix these before any audit

An auditor, a questionnaire and an attacker all start in the same place: who can reach which data, and where your keys live. For an app built with AI tools, these fixes come first, and every one of them is free:

The full sequence, lesson by lesson, is the Ship safely track.

Quick answers

Is SOC 2 legally required?
No. It is a voluntary attestation that customers ask for. HIPAA business associate agreements and GDPR data processing agreements are legal requirements when they apply to you.
SOC 2 or ISO 27001?
Ask your buyer. US enterprise buyers usually ask for SOC 2; EU, UK and Asia-Pacific buyers often accept or prefer ISO 27001. Many controls overlap, so the second one is cheaper than the first.
Does using Supabase, Vercel or AWS make my app compliant?
No. Their reports cover their platforms, not your application. Supabase's own docs say customers who want to be SOC 2 compliant need their own audit. You collect their reports as evidence.
Does the EU AI Act apply to my chatbot?
If you offer it in the EU, the transparency duties in Article 50 apply since August 2026: people must be told they're interacting with an AI. The high-risk obligations now start on 2 December 2027 and 2 August 2028.
Am I in scope for NIS2 as a small SaaS company?
Directly, only if you're medium-sized or larger in a listed sector. Indirectly, yes if your customers are in scope, because they must secure their supply chain and will pass requirements down to you.
Is the EU–US Data Privacy Framework still valid?
Yes, as of September 2026. An appeal is pending at the EU's Court of Justice, and we found no ruling yet. Standard contractual clauses remain the fallback for transfers.
How do I know a vendor's SOC 2 report is real?
Check that the auditor is a licensed CPA firm you can look up, read the report instead of filing it, and be wary of reports that look template-driven. In 2026 the AICPA told peer reviewers to watch for firms leaning on identical, platform-generated work.
Do I need a pen test for SOC 2 or ISO 27001?
Neither standard strictly mandates one, but most auditors expect some security testing and enterprise buyers often ask. A typical small-scope test runs about $5,000 to $15,000.

Start here